@soatok I'm running a few mail servers, and I had to set up explicit TLS for some destinations (basically, refuse unencrypted connections when delivering to specific domains; apparently that's deemed secure enough in some circles).
Had a funny anecdote, too – Let's Encrypt switched to ec certificates, which caused postfix to automatically disable some older encryption types, and suddenly one of those servers couldn't deliver to my client any more, because they were still running Exchange 2016 which does not support TLS 1.3…
Embed Notice
HTML Code
Corresponding Notice
- Embed this notice
Jernej Simončič � (jernej__s@infosec.exchange)'s status on Monday, 05-Jan-2026 07:15:29 JST
Jernej Simončič �